Skip to content

Commit 384340c

Browse files
committed
Require id-token write permissions from GitHub Actions to generate provenance report
1 parent ea3ae4e commit 384340c

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

.github/workflows/publish.yml

+6
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,9 @@ jobs:
2626
publish-npm:
2727
needs: build
2828
runs-on: ubuntu-latest
29+
permissions:
30+
contents: read
31+
id-token: write
2932
steps:
3033
- uses: actions/checkout@v4
3134
- uses: actions/setup-node@v4
@@ -40,6 +43,9 @@ jobs:
4043
publish-gpr:
4144
needs: build
4245
runs-on: ubuntu-latest
46+
permissions:
47+
contents: read
48+
id-token: write
4349
steps:
4450
- uses: actions/checkout@v4
4551
- uses: actions/setup-node@v4

0 commit comments

Comments
 (0)